The dbx revocation list shipped by the UEFI forum, revokes Fedora distribution secureboot bootloaders. They are in process receiving new signatures, but until they do, we chose to pause rollout of these revocations.
The new dbx revocation list is available from `-proposed` for a few series. https://launchpad.net/ubuntu/+source/secureboot-db => you will notice that for focal and earlier, there is updated secureboot-db update package that you can download and install. With those you will not be able to boot Fedora, and other derivatives that reuse Fedora secureboot bootloaders (at least at some time Arch Linux did that). ** Changed in: secureboot-db (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1911639 Title: dbxupdate of secureboot-db does not match revocation list provided by UEFI forum To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/secureboot-db/+bug/1911639/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs